Creating a SSID to provide WAN+Printer access

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Creating a SSID to provide WAN+Printer access

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Creating a SSID to provide WAN+Printer access
Creating a SSID to provide WAN+Printer access
2024-11-05 14:15:57 - last edited 2024-11-05 15:11:33
Model: ER7212PC  
Hardware Version: V1
Firmware Version:

Hello, 

 

I have an ER7212PC, 3 EAP615 APs and an EAP655 setup and working with a default LAN 192.168.0.0/19 with wired and wireless clients, and an SSID to provide isolated guest access to the internet WAN. The wired printer has a reserved IP address. Clients on my default LAN can discover and print to my wired printer; on the guest SSID they cannot.

 

I want to offer wireless access that provides client isolation and internet plus discoverable access to a wired network printer on my default LAN. Are there any examples that I can follow to achieve this, at least for iOS and Android clients?

 

To try to do this I have created an isolated/guest LAN on 192.168.255.128/25 (used only by wireless clients on SSID PrinterGuests, or via PPSK). These clients have only internet WAN access and are isolated from each other and other LANs by a pair of EAP ACLs. I've tried to create EAP ACLs to allow access to the open TCP ports on the printer but I cannot access the printer in my testing. Am I on the right track, or are there any other approaches?

 

 

===

Edit:

The rules above allow me to access the printer web configuration from the internet+print SSID using a web browser on port 80 or 443, but if I try to manually add the printer to the Epson app on Android it fails with the message "Communication Error. Check the network settings for this device." And, it isn't discovered in any iPad or Android app 🤷‍♀️

 

 

  0      
  0      
#1
Options
2 Reply
Re:Creating a SSID to provide WAN+Printer access
2024-11-06 01:40:50

Hi @RockPaper 

Thanks for posting in our business forum.

The router doesn't support IP-Port Group ACL yet.

As for now, I think what you requested is not possible to be done.

IP-Port group requires a switch and it does not apply to the router. So you need to do this with a switch and rules should be applied to the switch.

 

If you need the discovery to work, you should take a look at this guide: mDNS Repeater on the Router Doesn't Take Effect

 

  1  
  1  
#2
Options
Re:Creating a SSID to provide WAN+Printer access
2024-11-11 09:36:21

  @Clive_A 

 

Thanks - I found this helpful doc in the WiFi forum 

How to allow guest network to access specific device on the main network by configuring EAP ACL? - Business Community

(I just needed TCP and UDP protocols, rather than ALL.)

IP Port Groups are available for the EAP ACL rules, so maybe I could get it a little more locked down than the IP described in the article, but I have it working using the IP Group ACL.

 

Also thanks for the pointer to the mDNS page. I don't have it working yet, but that seems like configuration needed for printer discovery, so I'll keep poking it.

 

 

  1  
  1  
#3
Options